Cyber Security Application Remediation Governance Analyst
Immigration summary
Visa sponsorship
This employer sponsors, but not for roles like this one.
560 recent H-1B filings
View visa evidenceGreen card sponsorship
This employer has recently sponsored green cards at scale.
118 recent certified PERM filings
View green card evidenceJob description
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Position Summary:
The Application Remediation Governance candidate will contribute to reduction of technology risk in the bank by driving down the time taken to remediate identified application vulnerabilities, working with application managers and risk partners to resolve vulnerabilities in a time frame aligned to the Bank’s risk appetite.The candidate will be at the forefront of the Bank’s response to the new AI- identified application vulnerabilities, working with application teams and driving remediation in a timely manner.
The candidate will attend report out calls following a security assessment of a particular application aligned with an assigned 4 dot hierarchy. Candidate will track the identified vulnerabilities in the system of record and work with the application or vendor manager until resolution. Candidate will update status of vulnerabilities as required in the system of record and will aid the application and/or vendor manager with any technical or process related queries during resolution of the identified vulnerabilities. Additionally the candidate will be expected to aid with creation of periodic risk metrics relating to the role.
Responsibilities:
- Creates and maintains the team's application vulnerability portfolio.
- Responsible for being at the forefront of the Bank’s response to the novel threat of AI identified vulnerabilities, possession of a good understand of LLM based vulnerabilities and the most effective and timely actions the team can take to minimize cyber risk to the Bank.
- Oversight and leadership responsibilities for ARG daily BAU activities.
- Leadership of the ARG team, including being proxy manager when required.
- Responsible for maintaining a balanced distribution of vulnerabilities between ARG team members to ensure workload balance.
- Work includes configuration of the SOR for all team members to view their portfolio, specifically alerting them to any items that require timely action (e.g. self assignment of new vulnerabilities).
- Responsible for escalation and representation of the ARG on Incident calls related application vulnerabilities, specifically P1s.
- The candidate will be expected to take responsibility for any ARG actions or collaboration, “owning” the issue for ARG.
- Works with CST tech teams to ensure that the SOR remains up to date and functioning correctly.
- Works with CST on enhancements to the SOR.
- Represents ARG on tech calls relating to SOR, providing end user input and validation of break/fix activities.
- Responsible for management of the ARG BAU process for unmasked corporate account details.
- Responsible for creation and maintenance of ARG team official process and procedure documentation, and training documentation.
- Responsible for configuration of the application access package for all new ARG team members in ARM.
- Responsible for creation and QA for monthly risk metrics at manager and board level.
- Responsible for training and onboarding any new members of the ARG team.
Required Qualification
s:
- 3+ years cyber security experience.
- Vulnerability and remediation experience.
- Ability to improve team processes to increase efficiency and coverage. This would include maintenance of team documentation and optimising alignment of vulnerabilities among the team.
- Understanding of novel vulnerability vectors, primarily those aligned to AI capabilities.
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40
Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)
Pay and benefits information
Pay range
$99,200.00 - $145,000.00 annualized salary, offers to be determined based on experience, education and skill set.
Discretionary incentive eligible
This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
Benefits
This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
Sponsorship evidence
Why Openbound reached the conclusions above.
Visa sponsorship evidence
Current posting
Silent on sponsorship
Other openings
1 of 1992 recent openings at this employer state a sponsorship restriction.
Employer H-1B history
- 560
- recent certified H-1B filings
- 143
- new-hire petitions
- 0
- filings for similar roles
- 436
- so far in FY2026
More evidence details
- 560 recent certified H-1B filings across the employer
- Still filing this year — 436 filings in FY2026
- 1 USCIS H-1B new-employment approval, counted separately from LCA filings
- 9 further USCIS approvals for extensions or transfers
- We checked 297 filing titles for this employer and none describe work like this role
- 1 other recent posting at this company state a sponsorship restriction
- The posting says nothing about sponsorship either way
- No filing activity is recorded for this job's location
Green card sponsorship evidence
Employer PERM history
- 118
- recent certified PERM filings
- 0
- filings for similar roles
Filing history reflects past employer behavior; it isn't a promise for this opening.
All open roles at Bank of AmericaHow Openbound evaluates sponsorship
Visa history uses official U.S. Department of Labor H-1B LCA disclosure data and USCIS H-1B petition history. Green card history uses DOL PERM disclosure data. Each is read for the employer as a whole, for roles like this one, and for this location, weighted toward the most recent fiscal years.
An employer is matched to its filing entities by verified legal name and reviewed aliases; a match is never made on a name resemblance alone. Where no verified entity can be matched, the page says so and draws no conclusion from the absence. 297 filing titles were examined for this employer.
What this posting states outranks history in both directions, and an employer's published policy outranks past filings. Filing history reflects past behavior; it is not a promise of sponsorship for this opening, and none of this is legal advice.